ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Exploits for unauthenticated FortiWeb RCE are public, so patch quickly! (CVE-2025-25257)

criticalVulnerability exploited in the wildimportance 60CVE-2025-25257

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-25257
Critical Unauthenticated SQL Injection in Fortinet FortiWeb (CVE-2025-25257)

CVE-2025-25257 is a critical (CVSS 9.8) SQL injection flaw (CWE-89) in Fortinet's FortiWeb web application firewall, affecting FortiWeb 7.6.0 through 7.6.3, 7.4.0 through 7.4.7, 7.2.0 through 7.2.10, and 7.0.0 through 7.0.10. It can be triggered by an unauthenticated remote attacker sending crafted HTTP or HTTPS requests to the appliance, with no user interaction or credentials required. Successful exploitation lets the attacker execute unauthorized SQL commands or code on the device, and publicly released proof-of-concept exploits chain the flaw to remote code execution on the appliance. Any organization running an affected FortiWeb version is exposed, and because FortiWeb appliances are typically deployed at the network edge to protect web applications, internet-facing deployments are the most likely targets. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-07-18 and carries a 99.8% EPSS score with two public PoC exploits, so defenders should treat it as actively exploited.

Do: Upgrade FortiWeb to the latest patched build for your branch (7.0.x, 7.2.x, 7.4.x, or 7.6.x) per Fortinet's advisory, or apply the vendor's mitigations; federal agencies must follow the BOD 22-01 requirements tied to the KEV listing. Until patched, limit internet exposure of FortiWeb interfaces and review device and WAF logs for signs of exploitation, since public PoC exploits and the KEV addition on 2025-07-18 indicate active use.

9.8100% KEV PoC ×2
  • Fortinet FortiWeb 7.6.0 through 7.6.3
  • Fortinet FortiWeb 7.4.0 through 7.4.7
  • Fortinet FortiWeb 7.2.0 through 7.2.10
  • +1 more
largetens of thousands of internet-exposed FortiWeb appliances (estimated)
Full article421 words · extracted from helpnetsecurity.com · click to collapse

With two proof-of-concept (PoC) exploits made public late last week, CVE-2025-25257 – a critical SQL command injection vulnerability in Fortinet’s FortiWeb web application firewall – is expected to be leveraged by attackers soon.

CVE-2025-25257 exploits

About CVE-2025-25257

CVE-2025-25257 is found in FortiWeb’s Fabric Connector, the software that allows FortiWeb to communicate with other Fortinet security products (e.g., FortiGate firewalls, FortiSandbox, etc.).

The flaw stems from the solution’s failure to properly neutralize special elements and, if triggered, it may allow unauthented attackers to achieve remote code execution with root privileges, by executing unauthorized SQL code/commands via crafted HTTP or HTTPs requests.

Fortinet has patched CVE-2025-25257 last week, crediting prolific bug hunter Kentaro Kawane from GMO Cybersecurity with reporting it.

CVE-2025-25257 exploitation made easy

On Friday, watchTowr researchers published their own deep-dive into FortiWeb in search of the flaw, and released a script that attempts to detect if FortiWeb is vulnerable to CVE-2025-25257.

“An unauthenticated attacker can trigger SQLi via an HTTP request to the /api/fabric/device/status endpoint (and possibly several other endpoints, according to [watchTowr’s] analysis). The Authorization header will contain a Bearer value that forms part of an unsanitized SQL statement, leading to the SQLi,” Rapid7 security engineer Stephen Fewer succinctly explained the exploitation process outlined by watchTowr’s researchers.

“An attacker can leverage the SQLi to achieve RCE by creating several SQL statements to write a Python .pth file to a common Python site packages directory, and then indirectly triggering the execution of a known Python script via an HTTP request, which in turn will execute the attackers malicious pth file with root privileges.”

Another security researcher said they’ve unearthed CVE-2025-25257 in February 2025 but did not report it to Fortinet at the time. They’ve also published a working exploit for CVE-2025-25257 on Friday.

At the moment, there is no indication that the vulnerability is being actively exploited by attackers, but the situation might change quickly.

FortiWeb users would do well to mitigate the risk as soon as possible, either by upgrading their FortiWeb installation(s) to version 7.6.4 or above, 7.4.8 or above, 7.2.11 or above, or 7.0.11 or above; or by disabling the solution’s HTTP/HTTPS administrative interface.

UPDATE (July 19, 2025, 10:55 a.m. ET):

CISA has added CVE-2025-25257 to its Known Exploited Vulnerabilities catalog, after the Shadownserver Foundation reported that exploitation activity happened since July 11.

On July 16, the organization flagged 77 Fortinet FortiWeb instances compromised with webshells, likely via CVE-2025-25257.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/07/14/exploits-for-unauthenticated-fortiweb-rce-are-public-so-patch-quickly-cve-2025-25257/